Skip to content

ci: modernize GitHub Actions pipeline and enforce tri-layer code quality - #31

Merged
BGLuis merged 8 commits into
developfrom
feat/ci-modernization-and-code-quality
Oct 5, 2026
Merged

BGLuis merged 8 commits into
developfrom
feat/ci-modernization-and-code-quality

Conversation

@BGLuis

@BGLuis BGLuis commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Summary of CI/CD Modernization & Tri-Layer Code Quality

This pull request modernizes the continuous integration (CI) pipeline and activates robust code quality tooling across all three architecture layers of tucaVR (Rust, C++, and Kotlin/Android). It eliminates suppressed checks and restructures the CI workflow into fast, decoupled parallel jobs in accordance with industry best practices (ALVR, Android/Media3) and the GitHub Actions platform guidelines.


Key Changes by Component

1. Rust Layer (rust/)

  • Clippy --all-targets Fixes: Resolved 4 latent Clippy warnings in network integration tests (dash::stream, hls::segment, http, prefetch) that were previously masked because --all-targets was not run.
  • Uniform Workspace Formatting: Formatted Rust source and integration tests using cargo fmt.
  • Supply-Chain & License Auditing: Added rust/deny.toml with workspace crate clarifications to enforce allowed open-source licenses (MIT, Apache-2.0, BSD, ISC, etc.), scan for dependencies, and reject duplicate crate versions via standalone cargo-deny check (licenses, bans, sources).

2. Native C++ & Shaders (native/)

  • Coding Standards: Added .clang-format (C++20, 4-space indent) and formatted all project headers and host tests.
  • Vulkan Shader Validation: Created scripts/check-shaders.sh to validate the syntax of all 20 Vulkan shaders (.vert, .frag) on host CI using glslc / glslangValidator without requiring full APK compilation.
  • Host Test Sanitizers: Enhanced scripts/test-native-host.sh with AddressSanitizer (ASan) and UndefinedBehaviorSanitizer (UBSan) via ENABLE_ASAN=1 to detect memory leaks and undefined behavior during CI execution.
  • Bug Fix: Resolved a compilation error in vr_player_app_vulkan.cpp where scene.screenPos was incorrectly referenced instead of scene.screenCenter.

3. Android / Kotlin Layer (app/)

  • API Level Compatibility: Fixed a NewApi violation in ThermalMonitor.kt by using ContextCompat.getMainExecutor(context) for backwards-compatible execution on Android 8.0/8.1 (minSdk = 26).
  • Android Lint: Configured android.lint in Gradle with baseline = file("lint-baseline.xml") and abortOnError = true to catch future regressions in API levels, resource usage, and security.
  • ktlint Integration: Applied the official org.jlleitschuh.gradle.ktlint Gradle plugin with a baseline, turning ktlintCheck into an active, functional quality gate.

4. GitHub Actions CI Pipeline (.github/workflows/main.yml)

  • Decoupled Parallel Architecture: Replaced the monolithic serial build-and-lint job with 4 concurrent quality jobs plus the Quest 3 APK build:
    1. security-and-workflows: Runs actionlint (workflow static analysis), cargo-deny, and gitleaks (secret scanning).
    2. rust-checks: Runs rustfmt --check, cargo clippy --all-targets --all-features, and host unit tests.
    3. cpp-checks: Runs clang-format, check-shaders.sh, and native unit tests with ASan.
    4. android-checks: Runs ktlintCheck, lintDebug, and Kotlin JVM unit tests (testDebugUnitTest).
    5. build-apk: Full unified compilation of Rust + C++ + Android into Quest 3 APK.
  • Pipeline Hardening: Enforced least-privilege permissions: {} globally, explicit per-job permissions, pinned runners (ubuntu-24.04), and smart concurrency cancellation on pull requests.
  • Artifact Name Sanitization: Replaced illegal forward slashes in PR branch references with dashes during APK artifact upload.

Verification

  • All 5 CI Checks Passing:
    • Security & Workflows: PASS (16s)
    • C++ Native & Shaders: PASS (17s)
    • Rust Quality & Tests: PASS (2m 4s)
    • Android Lint & JVM Tests: PASS (3m 27s)
    • Build Quest 3 APK: PASS (8m 7s)
  • Local Validation:
    • cargo clippy -p protocols -p media-logic --all-targets --all-features -- -D warnings (PASS)
    • cargo test -p protocols -p media-logic (PASS)
    • ./scripts/check-shaders.sh (PASS, 20/20 shaders compiled)
    • ./gradlew ktlintCheck lintDebug testDebugUnitTest (PASS)

@BGLuis BGLuis self-assigned this Oct 5, 2026
@BGLuis
BGLuis merged commit 1ccfde3 into develop Oct 5, 2026
5 checks passed
@BGLuis
BGLuis deleted the feat/ci-modernization-and-code-quality branch October 5, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant